safe_mode for ISPs
| From: | Ole Tange | Date: | Wed, 24 Nov 1999 00:21:21 +0000 |
| Subject: | safe_mode for ISPs | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-13028@lists.php.net to get a copy of this message | ||
Keywords: safe_mode security ISP restricting access
Safe mode is not safe enough for ISP's with malicious users. This is the
reason why many ISP dare not run PHP on their web-hosts.
For ISP's to run PHP it must fulfill to the following requirements:
#1. Protect users against each others
- spying in other users' files
#2. Protect against abuse of the ISP's resources
- memory
- CPU
- bandwidth
#3. Protect against cracking/port-scanning other sites
In a quick review of the functions in PHP3 we have found the following
problems. The problems existed even with safe mode on.
a. symlink()
In safe mode you can symlink("/etc/passwd","passwd") and then read the
password file and the same goes for the other users' files. This does
not fulfill requirement #1.
b. set_time_limit()
By expanding the max_execution_time you can abuse CPU time. This does
not fulfill requirement #2.
c. fsockopen()
With fsockopen you can make a port scanning of a remote network. This
does not fulfill requirement #3.
We are confident that there are a lot more functions that can be abused by
a malicious user. We therefore suggest creating a working group that will
make a safe_mode that is safe enough for ISPs to use.
best regards
Hans Schou and Ole Tange